{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"deadweight_loss_reduction__computer_science","trajectory_id":"R","attempt_index":0,"archetype_slug":"deadweight_loss_reduction","domain_slug":"computer_science","decision":"CANDIDATE","problem_id":"static_ci_runner_quota_misallocation","causal_lever_id":"revocable_idle_runner_quota_borrowing","proposal":{"problem":"Static per-team or per-repository CI-runner quotas can leave reserved execution slots idle while other teams' ready jobs queue, lengthening software-feedback cycles even when aggregate runner capacity is available. The quotas legitimately provide isolation, predictable access, and fairness, but their non-transferability may create avoidable allocation loss.","actors_substrate":["software developers and repository owners","CI platform scheduler and runner pool","platform engineering and SRE operators","security and compliance owners","teams holding reserved runner quotas"],"observable_state":"During overlapping intervals, eligible CI jobs wait behind an exhausted local quota while compatible slots reserved to other tenants remain idle; HYPOTHESIS: this state accounts for a material share of queue time after controlling for total pool saturation, runner compatibility, and security boundaries.","consequence":"Available compute produces no work while queued builds delay feedback, integration, and deployment; teams may respond by inflating priority, duplicating runners, or bypassing normal CI paths.","affected_objective":"Reduce avoidable CI queue latency and idle compatible capacity without weakening tenant isolation, minimum access guarantees, workload compatibility, or deployment controls.","structural_mapping":[{"archetype_element":"value-blocking wedge","domain_realization":"Non-transferable static concurrency reservations prevent queued compatible jobs from using temporarily idle slots.","claim_kind":"HYPOTHESIS"},{"archetype_element":"mutually beneficial or system-valued activity","domain_realization":"A borrowing repository receives earlier test results while the lending repository retains enforceable minimum capacity and reclaim rights.","claim_kind":"INFERENCE"},{"archetype_element":"protected purpose","domain_realization":"Per-tenant reservations preserve predictable access, fairness, security isolation, and containment of noisy neighbors.","claim_kind":"INFERENCE"},{"archetype_element":"idle capacity and queue symptom","domain_realization":"Compatible runners are simultaneously idle in one allocation and unavailable to ready jobs in another.","claim_kind":"HYPOTHESIS"},{"archetype_element":"bounded redesign","domain_realization":"Permit revocable borrowing only from demonstrably idle quota, subject to compatibility, floors, caps, and automatic rollback.","claim_kind":"HYPOTHESIS"}],"component_map":[{"component":"Distortion Map","status":"direct","domain_realization":"Join job-wait intervals to compatible-runner idleness and identify waits caused specifically by quota boundaries."},{"component":"Protected Constraint Safeguard","status":"direct","domain_realization":"Preserve isolation, workload labels, per-tenant floors, emergency headroom, and existing release gates."},{"component":"Surplus Estimate","status":"adapted","domain_realization":"Estimate reclaimable runner-minutes and queue-minutes, reporting ranges rather than monetizing all developer delay."},{"component":"Affected-Party Incidence Map","status":"direct","domain_realization":"Record benefits and harms for borrowers, quota holders, operators, and security owners."},{"component":"Redesign Lever","status":"direct","domain_realization":"Allow capped, revocable execution of compatible queued jobs on another tenant's idle reservation."},{"component":"Distributional Review","status":"direct","domain_realization":"Compare latency and access by tenant size and workload class, including whether small teams lose predictability."},{"component":"Behavioral Response Model","status":"adapted","domain_realization":"Model priority inflation, job splitting, demand rebound, strategic reservation, and preemption waste."},{"component":"Implementation Boundary","status":"direct","domain_realization":"Limit the pilot to non-production test jobs in one compatible runner pool and selected consenting repositories."},{"component":"Monitoring and Rebound Check","status":"direct","domain_realization":"Track queue percentiles, utilization, reclaim events, failed jobs, preemption cost, and tenant-level regressions."},{"component":"Rollback or Adjustment Rule","status":"direct","domain_realization":"Disable borrowing and restore static reservations automatically when guardrail thresholds are crossed."},{"component":"Cost–Benefit Assessment Frame","status":"adapted","domain_realization":"Compare reclaimed feedback time with scheduler complexity, interruptions, operational burden, and distributional effects."},{"component":"Price-Wedge Diagnostic","status":"omitted","domain_realization":"No monetary price is posited; test and reject pricing as the binding explanation."},{"component":"Friction Source Breakdown","status":"direct","domain_realization":"Separate quota blocking from genuine saturation, runner incompatibility, dependency waits, and security restrictions."},{"component":"Compensating Adjustment Plan","status":"adapted","domain_realization":"Protect lending tenants through reserved floors, instant reclaim, borrowing caps, and optional exclusion."},{"component":"Legitimacy and Authority Review","status":"direct","domain_realization":"Confirm the platform owner may reallocate only unused service capacity and cannot override repository or security policy."},{"component":"Sensitivity Analysis","status":"direct","domain_realization":"Vary compatibility assumptions, reclaim cost, demand response, and the attribution of developer delay."},{"component":"Pilot or Sunset Path","status":"direct","domain_realization":"Run an automatically expiring pilot whose continuation requires measured improvement without guardrail breaches."}],"mechanism_dispositions":[{"slug":"congestion_or_capacity_pricing_adjustment","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Job value is not reliably represented by willingness to pay, and internal pricing could undermine access fairness.","counterfactual_removal":"No change; the proposed causal chain does not use prices."},{"slug":"cost_benefit_assessment_protocol","disposition":"selected_supporting","contribution_type":"TEST_DESIGN","adaptation_or_rejection":"Use latency, capacity, reliability, and incidence ranges rather than a single monetary welfare figure.","counterfactual_removal":"The pilot could run, but its continuation decision would obscure operational and distributional tradeoffs."},{"slug":"distortion_reduction_review","disposition":"selected_supporting","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Diagnose simultaneous compatible idleness and quota-blocked demand before treating the quota as avoidable.","counterfactual_removal":"True scarcity or incompatibility could be misclassified as quota distortion, invalidating the intervention."},{"slug":"impact_assessment_table","disposition":"selected_supporting","contribution_type":"SAFETY_GUARDRAIL","adaptation_or_rejection":"Report outcomes and thresholds separately for borrowers, lenders, and operators.","counterfactual_removal":"Aggregate utilization gains could conceal concentrated latency or reliability harm."},{"slug":"matching_improvement_program","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Jobs and compatible runners are already discoverable; the hypothesized barrier is allocation authority, not matching.","counterfactual_removal":"No change unless measurement instead reveals compatibility discovery as the binding failure."},{"slug":"permit_or_approval_streamlining","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"The queue is computational admission, not duplicated human approval, and substantive gates remain untouched.","counterfactual_removal":"No change."},{"slug":"price_control_redesign","disposition":"incompatible","contribution_type":"NONE","adaptation_or_rejection":"There is no administered monetary price or compensating payment in the proposed system.","counterfactual_removal":"No change."},{"slug":"quota_or_allocation_rule_review","disposition":"selected_load_bearing","contribution_type":"CORE_CAUSAL","adaptation_or_rejection":"Keep the aggregate capacity and protected reservations while making only idle allocations temporarily borrowable and revocable.","counterfactual_removal":"Removing allocation-rule reform leaves queued jobs unable to reach idle compatible slots, breaking the causal chain."},{"slug":"regulatory_simplification_pilot","disposition":"selected_supporting","contribution_type":"OPERATIONAL","adaptation_or_rejection":"Translate the walled-off, expiring pilot into a limited scheduler experiment with telemetry and automatic reversion.","counterfactual_removal":"The intervention becomes an unjustified broad scheduler change rather than a bounded test."},{"slug":"sunset_clause_review","disposition":"considered_rejected","contribution_type":"NONE","adaptation_or_rejection":"Sunset the experimental borrowing rule, not the underlying protective quota regime; the pilot mechanism already supplies expiry.","counterfactual_removal":"No material change because pilot expiration and rollback remain."},{"slug":"tariff_fee_or_toll_redesign","disposition":"incompatible","contribution_type":"NONE","adaptation_or_rejection":"No authority-imposed charge is the hypothesized wedge.","counterfactual_removal":"No change."}],"causal_chain":["Static, non-transferable tenant quotas partition a compatible runner pool.","Demand varies across tenants, producing simultaneous local queues and idle reservations.","The scheduler lends only verified idle capacity while preserving floors, compatibility, and reclaim rights.","More previously blocked jobs begin execution without increasing physical capacity or overriding safeguards.","If reclaim and gaming costs remain bounded, compatible idleness and quota-attributable queue latency decline."],"baseline":"Ordinary operation uses fixed per-tenant concurrency caps and FIFO or local-priority queues; excess demand waits, idle reserved slots are not lent, and operators handle exceptional pressure manually.","nearest_rival":"Autoscale or purchase additional runners for the congested tenants. That addresses genuine undersupply but is slower or wasteful if compatible capacity already sits idle; it becomes preferable if the pool is broadly saturated or borrowing causes harmful interference.","authority_safety":{"affected_parties":["developers whose jobs borrow capacity","teams whose reservations may be lent","CI platform and SRE operators","security and compliance owners","release stakeholders affected by feedback latency"],"decision_authority":"The CI platform owner may authorize the scheduler pilot jointly with SRE and security owners; participating repository owners authorize inclusion, while existing security and deployment authorities retain their gates.","authorized_first_step":"For two weeks, enable capped borrowing for non-production test jobs from a small set of consenting repositories within one security-equivalent runner pool; preserve tenant floors, allow immediate reclaim, and compare against matched baseline periods.","excluded_actions":["sharing runners across security or data-residency boundaries","reducing guaranteed tenant floors without consent","bypassing authentication, test, review, or deployment approvals","including production deployment jobs","permanent rollout before pilot review"],"halt_rollback":"Immediately disable borrowing and return to static quotas if any isolation breach occurs, failed or lost jobs exceed the predeclared threshold, a lending tenant's protected queue-latency bound is breached, or reclaim instability persists; otherwise the pilot expires automatically at two weeks."}},"negative_tests":{"strongest_counterevidence":"Historical traces may show that ostensibly idle runners are incompatible, deliberately held as failure headroom, or idle only for intervals shorter than safe dispatch; alternatively, most queues may coincide with full compatible-pool saturation. Any of these would leave little recoverable quota loss.","analogy_break":"CI scheduling is not voluntary exchange: job value is difficult to observe, capacity is heterogeneous, and reclaiming a borrowed runner can destroy partial computation. Consequently, higher utilization is not equivalent to greater welfare, and protective reservations may be productive redundancy rather than idle surplus.","failure_condition":"Borrowing increases utilization but preemption, cache loss, interference, gaming, or scheduler complexity offsets the latency benefit or disproportionately harms lending tenants.","problem_falsifier":"The problem is falsified if synchronized traces show no material intervals in which quota-blocked ready jobs coexist with idle, security-compatible, dispatchable runners after required headroom is excluded.","intervention_falsifier":"The intervention is falsified if the bounded pilot does not reduce quota-attributable queue time relative to baseline, or if it breaches any isolation, reliability, tenant-floor, or distributional guardrail.","risks":["cross-tenant information leakage through caches or shared infrastructure","priority inflation and strategic job splitting","reclaim thrashing and wasted partial work","small tenants losing predictable access","demand rebound recreating congestion","measurement bias from unrepresentative pilot repositories","scheduler complexity increasing outage risk"]},"null_rationale":null,"classification":{"candidate_kind":"MECHANISM_ADAPTATION","prior_art_status":"UNSEARCHED","evidence_maturity":"HYPOTHESIS"},"revision_change_log":{"revision_kind":"ORIGINAL","prior_problem_id":null,"prior_causal_lever_id":null,"problem_changed":false,"causal_lever_changed":false,"conceptual_changes":[],"operational_changes":[],"repairs_addressed":[]},"confidence":0.82,"generator_notes":"Closed-book structural inference. The candidate depends on the empirically testable distinction between allocation-induced idleness and genuine capacity scarcity; no novelty or measured effect is claimed."}